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We report an experimental demonstration of effective entanglement in a prepare&measure type 
of quantum key distribution protocol. Coherent polarization states and heterodyne measurement 
to characterize the transmitted quantum states are used, thus enabling us to reconstruct directly 
, their Q-function. By evaluating the excess noise of the states, we experimentally demonstrate that 

' they fulfill a non-separability criterion previously presented by Rigas et al. [J. Rigas, O. Giihne, N. 

f"**) ' Liitkenhaus, Phys. Rev. A 73, 012341 (2006)]. For a restricted eavesdropping scenario we predict 

, key rates using postselection of the heterodyne measurement results. 
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I. INTRODUCTION 



■ The process of Quantum Key Distribution (QKD) 0, 0] uses quantum mechanical properties of light fields to 
' establish a secret shared key between two honest parties, named Alice and Bob. This key is then used to ensure secret 

communication between Alice and Bob by means of a classical cipher like the one-time-pad 3] . The adversary of Alice 
and Bob is an eavesdropper Eve, who tries to gain the maximum knowledge about the key without being noticed by 
Alice and Bob. Eve can use any method within the laws of quantum mechanics, and therefore is not restricted by 
C — ■ technological imperfections. 

I The physical implementation of a QKD protocol requires two channels between Alice and Bob. Over the quantum 

■ channel Alice and Bob can exchange quantum states. By the laws of quantum mechanics Alice and Bob are able to 
detect any interference of Eve with the quantum states. Classical information is exchanged on the classical channel. 
This channel has to be authenticated in order to prevent a man-in-the-middle attack by Eve. 

After the quantum states have been exchanged over the quantum channel, they are measured by Bob. Alice and 
Bob keep the results of the preparation process and the measurement process, thus sharing a set of classical correlated 
measurement data described by the joint probability distribution p{A; B). This is the first stage of the QKD protocol. 
\ In the second stage, Alice and Bob try to generate a key pair from their correlations p{A] B) and correct possible 
^ ' errors. From the disturbance of the correlations they deduce the amount of information Eve might have on the key 
^ pair, and reduce Eve's information by privacy amplification. For these tasks, only communication over the classical 
channel is needed, as all exchanged information is classical. If the QKD is successful, Alice and Bob will share a key 
^ ' and have an upper bound on the information Eve might have about it. 
• I— I . It has been shown by Curty et al. 0,13 that there is a necessary precondition for the second stage to succeed: The 

■ correlations p{A] B) coming from the first stage have to be created from an effective entangled quantum state shared 
^ \ between Alice and Bob. Only then it is possible to generate a secret key from the data set. Note that this 'effective 
- - ' entanglement' does not mean that entanglement as a physical resource has to be used in the state preparation step. 

It is sufficient that Alice and Bob can model their correlations as if they had shared an entangled state. We use an 
entanglement witness to check if the correlations show effective entanglement. 

In this paper, we demonstrate this effective entanglement for a particular implementation of the quantum channel. 
We present a prepare&measure type setup, which uses the polarization of coherent light pulses to generate nonorthog- 
onal quantum states. The pulses are characterized by a heterodyne measurement Q on Bob's side, allowing for a 
reconstruction of their antinormal ordered quasi-distribution, or Q-function 0. We show for this particular system 
that we can prove effective entanglement for the prepared quantum states using a model developed by Rigas et al. 
[^Q. Thus, it has clearly the potential of generating secret keys. Following this, we use a reasonable model to predict 
key rates for a classical key generation process with the data obtained in stage one of the experiment. It considers 
postselection |lOj| with direct or reverse reconciliation .11] of the measurement data. This QKD protocol is known to 
be secure against an adversary Eve who is restricted to beam splitting attacks [T3 |. 

The paper is divided into five subsections. In section II we briefly introduce the theoretical background of the 
entanglement verification process, as it is described by Rigas et al. [1,13 ■ We also present the QKD quantum state 
protocol there. In section III we give a characterization of the experimental apparatus which implements the quantum 
stage of the QKD system. Section IV shows how the Q-function can be experimentally reconstructed and how the 
effective entanglement of the QKD setup can be verified. Section V gives achievable key rates for our experiment 
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applying a postselection procedure. 



II. PREPARE&MEASURE QUANTUM KEY DISTRIBUTION AND VERIFICATION OF EFFECTIVE 

ENTANGLEMENT 

The existing QKD systems fall into two categories: entanglement based systems and prepare&measure systems. 
For a review on both see e.g. jT3.] . In entanglement based systems, a bipartite entangled state is produced by a source 
which might even be under Eve's control. One part of the entangled state is then sent to Alice while the other is sent 
to Bob. Here Alice and Bob can directly verify the entanglement of the state, thus bounding any interaction of Eve 
[T^ . Then privacy amplification can be understood as an entanglement distillation (see e.g. Shor and Preskill 15j). 

In a prepare&measure system Alice prepares a quantum state and sends it through the quantum channel to Bob 
[3.ll6j|. He characterizes the quantum state, and from Alice's preparation and Bob's measurement results they estimate 
Eve's action and information on the quantum state. As sources of entangled states are hard to implement and suffer 
from technical disadvantages, we use the latter approach in our experiment, which ensures stable, deterministic state 
preparation with minimum resources. 

In our protocol Alice encodes her bit values into two nonorthogonal states as in the B92 protocol 16]. In particular, 
she prepares coherent states with the amplitudes —a or +a. A general coherent state can be described in a Pock 
state basis by 

— \Jn\ 

where n is the photon number, and \n) a photon number eigenstate. The coherent states constitute an overcomplete 
basis set, because there is always an overlap between two coherent states with amplitudes a and /3, as given by 

(/3|a)=e-^l'5-"l'. (2) 

Thus it is impossible to discriminate between the coherent states | — a) and | + a) with certainty [TtI IT^ ITgl |20| . 
The coherent states emitted by Alice are transmitted through the quantum channel, which is under the control of the 
eavesdropper Eve. She can manipulate the states and adjust the channel properties to get an advantageous position 
in the key generation process. As the states enter Bob's measurement station, he performs a heterodyne measurement 
1^, in contrast to the original B92 setup, where a photon counter is used to discriminate between the different states. 
The heterodyne measurement splits the optical mode on a 50/50 beam splitter and measures the two conjugate field 
quadratures on its outputs with two homodyne detectors. This measurement of two conjugate observables (see e.g. 
|2lL l22|l corresponds to a projection on coherent states. The quadrature operators are derived from the creation and 
annihilation operators and a by: 

X = i(at + a); Y ^ {a^ - a) . (3) 

Bob records the results of the heterodyne measurement in a two-dimensional histogram, which represents the Q- 
function 0, S m m m 113 : 

Q(Re/?;Im/3) = i(/3|p|/3). (4) 

TT 

Here, the general state p is projected onto the coherent state |/3). 

To model the prepare&measure setup with effective entangled states, we follow Bennett et. al. |2^ and assume 
that Alice possesses a source of bipartite quantum states given by 

\'^)Ahce^Bob = --^|*o)aS + -^|«'i)aB, (5) 

whereas the states |^'o,i)ab are given by 

|*o)aB = |0)Alico <8) I - a)to Bob , 

= |l)Alicc «) I + a)to Bob ■ (6) 

The model setup is shown in Fig. ^ Alice keeps the first part of the state, which consists of a qubit, and sends the 
other part of the state over the quantum channel to Bob. By detecting her qubit, Alice effectively prepares a coherent 
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FIG. 1: Simplified theoretical setup. 



state of amplitude —a or +a as signal. Thus, conditioned on her qubit measurement result, Alice produces a certain 
coherent state. As her measurement result, or 1, is occurring completely randomly, but also completely correlated 
with the generated coherent state, the entanglement source resembles the random production of coherent states with 
amplitudes —a or +a. In reality, such a random production of coherent states can be enabled without the use of an 
entanglement source, but in the theoretical description there is no difference between these two physical systems. 

The coherent states travel over the quantum channel, where Eve can interact with them. Also channel losses are 
attributed to Eve, as she can always replace a lossy channel with a lossless one and tap off the surplus intensity. 
When Eve has interacted, the pure coherent states might have changed to more general mixed states described by the 
density matrices pi and p2- From the results of the heterodyne measurement. Bob can reconstruct the Q-function, 
and deduce the quadrature variances A^X = (X^) — (X)^ and A^Y = (Y^) — (Y)^ and all other elements of the 
covariance matrix. 

As the full joint density matrix of Alice and Bob is not accessible by heterodyne measurements and dichotomic 
preparation, we revert to the bipartite expectation value matrix defined in Q to describe the state shared by Alice 
and Bob. It consists of a part A describing Alice's state preparation, and a part B describing Bob's heterodyne 
measurement 



|0)(0|a®B) (|1)(0|a®B 
|0)(1|a®B) (|1)(1|a®B 

with the matrix B composed of the quadrature operators directly accessible to Bob: 



(7) 
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(8) 



It has been shown 0, that an expectation value matrix with certain restrictions can only be justified by assuming 
that an entangled state is shared between Alice and Bob. This is done by using a separability criterion (positive 
partial transposition type). To verify this, only the blocks on the diagonal of x have to be computed. These are given 
by the expectation values corresponding to matrix B for the two conditional signal states and are therefore completely 
characterized by Bob's quadrature measurements. By proving this effective entanglement from the experimental data 
0, we can fulfill the first precondition to generate a secret key from Bob's and Alice's correlations. The separability 
condition can be evaluated by semi-definite programming p9| . giving an upper bound on the tolerable noise A^X, A^Y 
below which the effective entanglement can be verified. This bound depends on the input state overlap {—Oi\ +a) and 
the quantum channel loss. We define the excess noise or excess variance E of an observable X for a signal state by 
comparing its variance to the variance of a coherent vacuum state (shot noise) as 



E{X) = 



A2X(signal) 
A2X( vacuum) 



1. 



(9) 



Figure 121 shows the numerically calculated bounds to the excess variance for different quantum channel transmissions. 
All experimental excess variances which are below their corresponding bounds fulfill the non-separability condition 
and thus the scheme exhibits effective entanglement. 



III. EXPERIMENTAL APPARATUS 



The experimental setup deviates from the theoretical description in the previous section in one aspect. To determine 
the quadratures X and Y, Bob has to use a phase reference as local oscillator for the homodyne measurements P. l3Qj . 
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FIG. 2: Graphical representation of the entanglement criterion. For excess variances E (in shot noise units; SNU) below the 
curves, the correlated data p{A; B) cannot be explained by separable states. Zero excess variance corresponds to the detection 
of a pure coherent state. Different curves belong to different quantum channel transmissions T. 



This phase reference is sent along with the signal state in our experiment, as it is done in most continuous variable 
quantum cryptography experiments |^ |3^ |33, 0, |3^ [s^ . The analysis of quantum correlations does not directly 
apply to this new situation. However, there is no obvious possibility for Eve to manipulate the local oscillator in 
her favor, as it is a classical signal, and its phase can be publicly announced by Alice and Bob without giving away 
any information about the signal state. Moreover, Bob can use his own local oscillator and phase lock it to Alice's 
local oscillator, as described in [s^l, so that all that Eve can do to the local oscillator is to introduce phase jitter, 
which disturbs Bob's measurements without giving Eve any information on Alice's quantum states. In that case, the 
previous analysis would apply again. From now on we assume that the local oscillator is not manipulated by Eve in 
any way. 

Consequently our experimental realization of the quantum channel has to transmit two light modes: the signal field 
mode a contains the weak coherent pulses in which the quantum information is encoded. The local oscillator mode 
b is needed in the heterodyne measurement of the signal mode as a phase reference. Instead of using two spatially 
separated channels to transmit the two modes, we use two orthogonal polarization modes as representing the two fields 
in one spatial mode. This facilitates the generation of the signal states as well as providing high quality interference 
of the two modes at the heterodyne detector. The amplitude and relative phase of the two orthogonal polarization 
modes can be described by the Stokes parameters js^ or by the Stokes operators liol Elj in quantum theory. In 
our notation they read: 

50 = a)a + h'^h, (10) 

51 = a)a-b%, (11) 

52 = a)b + h^a, (12) 

53 = -i{a)h-h^a). (13) 

The intensity in the local oscillator mode b is always much larger than the intensity in the signal mode a, thus we 
have (^o) ~ —{Si) ^ 0, {S2) ~ 0, (S'3) ~ 0. The relative phases and amplitudes of the polarization modes can be 
manipulated with birefringent optical elements and polarizing beam splitters. 

A schematic drawing of our setup is shown in Fig. |3| An external cavity laser diode emits continuous wave light 
at 810nm and by a polarizing beam splitter acting as polarization filter a coherent bright state is created in the local 
oscillator mode b whereas the signal mode a is in the vacuum state. The light passes through an magneto optical 
modulator that utilizes the Faraday effect to alter the polarization state |42|. Depending on the externally applied 
magnetic field, the modulator rotates a linearly polarized input field and shifts the phase of circular polarized fields. 
The light polarization can be varied continuously from Si-polarized to S2-polarized, which corresponds to equal 
optical power in the a and the b modes. In our case, we only induce a very tiny modulation, such that for the optical 
powers Pa,Pb in the two modes Pf, ^ Pa is always satisfied. The modulation is applied in pulses of 5^s duration. 
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FIG. 3: Simplified experimental setup. Alice prepares coherent polarization states with a cw laser diode and a Faraday mod- 
ulator. Bob characterizes the incoming light by a heterodyne measurement consisting of two polarization sensitive homodyne 
setups. Eve is simulated by changing the foss of the quantum channel. 
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FIG. 4; Demonstration of a detected signal in the time domain. Ten identical measurements were superimposed to show the 
variations in detector voltage due to quantum noise. The pulse duration was set to 50/xs at a sample rate of IMSample/s to 
better visualize the pulse shape and the discrete nature of the sampled data. In the further experiments, a pulse duration of 
5/is was used. 



either with parallel or antiparallel magnetic field orientation, such that either the state | + a) or the state | — a) is 
produced in the a mode. The state overlap (+a| — a) — e^^'"' is in the range from 0.2 to 0.8. When encoding 
the signal, the intensity in the local oscillator mode is reduced only by a negligible amount (intensity variations are 
smaller than 10~^ in our experiment). Therefore, a local oscillator of constant power can be assumed. As the signal 
field is derived from the local oscillator field through modulation, the relative phase of both fields is constant, even 
though the laser phase might suffer from fluctuations. 

The beam is then directed to Bob, traveling through Eve's domain over a free space link of approximately 20cm. 
Various quantum channel transmissions can be simulated by using neutral density filters to equally attenuate both 
modes a and b. 

In Bob's receiver, the incoming beam undergoes a heterodyne measurement. It is split on a polarization independent 
50/50 beam splitter, and both parts are directed to individual homodyne measurement setups, which record the S2- 
polarization and Ss-polarization respectively. This is done by interfering the signal and the local oscillator modes on 
a beam-splitter and subsequently recording the intensity difference at the beamsplitter output ports 30, 
long as the local oscillator mode is much brighter than the signal mode, the difference photocurrent / corresponds to 

I Qc ^/P'b\/K cos (f> (14) 

with Pj, being the local oscillator optical power and Pa the signal optical power, and the relative phase between 
signal and local oscillator. The relative phase of signal and local oscillator in our setup is controlled by the appropriate 
choice and setting of half wave plates (HWP, S2 measurement) and quarter wave plates (QWP, S3 measurement). 
The two modes interfere at polarizing beam splitters. As both the signal and the local oscillator are in the same 
spatial mode, a very high interference contrast can be achieved. We record a polarization contrast larger than 10'^, 
corresponding to an interference visibility larger than 99.9%. Both homodyne detector voltages are sampled with a 
fast A/D converter. Figure^ shows 10 superimposed test pulses with high amplitude in the a mode. Each point 
corresponds to one sample. It can be seen that one polarization pulse is much longer than one sample period. The 
variance of the sampled data is an indicator for the shot noise of the signal light mode. For the experiments, a sample 
rate of 20MSample/s and a pulse duration of 5/xs was chosen. Consequently, an integration over 100 Samples defines 
our pulse amplitude. The electronic and dark noise of the detectors is more than 14dB below the signal noise in a 
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FIG. 5: Marginal distribution of the measured polarization values. The dotted black curve represents the shot noise reference, 
recorded with vacuum in the signal mode as- The solid grey curve is Bob's measurement value histogram for two alternating 
states, corresponding to Fig. |5] and the highlighted line in Table |I] 

frequency window from lOOHz to 2MHz with a local oscillator power of Pb =1.2mW. Dark noise at higher frequency 
is fihered by a 2MHz low pass filter. From the pulse amplitudes, the quadratures and polarizations are calculated by 
measuring the local oscillator power, and the detector transimpedance (approx. llOkfi) as well as the diode quantum 
efficiencies (91% ± 3.5%). 

With the pulse separation of 10/is a clock rate of lOOkPulse/s is feasible. As we characterized five vacuum noise 
time slots for each bright signal pulse, the effective clock rate for signal pulses was reduced to 16.7kPulse/s for the 
Q-function and effective entanglement measurements. In the real QKD system, the vacuum characterization is only 
needed for an initial calibration, and the full clock rate can be used for pulse transmission subsequently. 

A whole measurement sequence consists of 250000 signal pulses. A histogram of recorded pulse amplitudes in the 
S2 polarization (corresponding to a or tt phase shift between signal mode a and local oscillator mode b) is shown 
in Fig. |31 The shot noise reference is produced with no modulation current (vacuum mode) and is shown in black 
(dotted). The grey histogram is derived from the signal pulses with amplitudes —a and +a. The overlap of the two 
resulting Gaussian distributions is too high to distinguish between them in this histogram, the only visible effect is a 
decrease in peak height and an increase in variance. 

The variances of the polarization (or quadrature of the a mode) measurement can be used to calculate the appro- 
priate entries of the x-ma-trix (cf. Eqn. [71). The Q- functions were reconstructed by building a histogram of the S2 
and S3 values and renormalizing the volume of the resulting two dimensional function. From the definition of the 
Q-function of Eqn. 21 it follows that its peak value is maximal for pure coherent states. Thus a rough measure for 
the purity of the states measured by Bob is the peak height of his Q-function for each type of state Alice prepared. 
The absolute height of the measured functions is in accordance with the total losses measured for diode efficiency 
and optical losses in the detection setup, which sum up to 13.6%. It is assumed that these losses cannot be actively 
used by Eve. For the entanglement criterion, the excess noise variance (cf. Eqn.O is used, which compares the signal 
variance with the vacuum variance. As the vacuum variance is determined with the same setup, the detection losses 
are not regarded in the further analysis. 

IV. RESULTS 

The restrictions for the quadrature variances given by the entanglement criterion of Rigas et al are shown in 
Fig.|nifor the relevant parameter range. The curve shows the maximum measured excess variance E compared to the 
coherent vacuum state, that is tolerable without having a separable state. As it can be seen, all measurement results 
(diamonds) lie below this threshold. Therefore the joint probability distribution can only be explained by effective 
entanglement in the whole shared state between Alice and Bob. Numerical values are compiled in Table |l| For each 
measurement, a separate evaluation of the vacuum variance (shot noise level) was calculated from the vacuum pulses 
transmitted during the measurement. The state overlap prepared by Alice is shown in the first column. The second 
column gives the quantum channel transmission, where losses in Bob's detection unit are not taken into account. 
The third column gives the excess variance £'(82) of Bob's polarization measurements compared to the vacuum 
variance. The fourth column gives the excess variance £'(83) of the S3 polarization. Apart from one value, all excess 
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FIG. 6; Graphical representation of the entanglement criterion. For excess variances below the curves, the correlated data 
p{A; B) cannot be satisfied by separable states. Different curves correspond to different quantum channel losses. The open 
diamonds show measured averages of -£(82) and _B(S3), their numerical values can be seen in TableQ] 
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TABLE I: Excess variances E for the coherent state measurement, depending on state overlap and quantum channel transmis- 
sion. The statistical error is ±0.5 for -£(82) and ±0.3 for _E(83). The last column gives the excess variance with the electronic 
noise subtracted only from the shot noise reference which refers to a worst case scenario. The highlighted line shows the data 
set that produced the Q-function in Fig. |5] and the marginal distribution in Fig. |S] 



variances fall well below 1%, whereas more than 10% are enough to prove effective entanglement with the given 
quantum channel transmissions. Note that negative excess variances are no sign of nonclassical states but represent 
the statistical variations due to the finite sample size. The average excess variance is given by £'(82) — 0.4±0.5% and 
-£(83) = 0.0 ±0.3%. To give a conservative estimate on the impact of electronic noise on our measurement results, we 
subtracted the variance of the electronic noise only from the shot noise reference. The excess variances are compared 
to this corrected vacuum state are given in column five. They are all still below 9%. Even with this conservative 
correction we witness the presence of effective entanglement. 

Fig. shows the reconstructed Q-function of the vacuum state. This function is a direct histogram, and has not 
been smoothed or fitted. In Fig.|Slwe depict the Q-function of the mixed state p — ^\ + Q!)(±a| ± ^| — a){—a\ with 
an overlap (— a] ± a) =0.51 measured with no channel loss. From the figure it can be seen that the height of the 
Q-function is an indicator to mixedness of the depicted state. Here the mixture of pi and p2 states with no additional 
quantum channel loss gives a Q-function with a peak height that is distinctively less than that of the pure vacuum 
state. After a loss of 54.3%, the mixedness of the state is decreased (cf. Fig. (S)). This Q-function corresponds to the 
highlighted line in Tableland the grey histogram in Fig.|31 

If Alice reveals to Bob which pulse belonged to the state \^o)ab and which to the state \^i)aBj Bob can produce 
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FIG. 7: Vacuum noise Q-function. S2 and S3 are proportional to the X and Y quadrature of the signal mode a. The peak 
height is indicated by the grey line. 




FIG. 8: Mixed Q-function of the two signal states p\ and p2 after leaving Alice's preparation. 



two histograms. They are both shown in Fig. ^1 The two Gaussian distributions represent the states Bob receives 
of Y^oiAB [pi — \ ~ a){—a\ ideally) and of \^o)ab {p2 = \ + a){+a\ ideally). The overlap (cf. Eqn. [2Jl can be seen 
at the intersection of the two distributions (S2 coordinate is zero). This overlap increases as losses are introduced. 
Fig. II II shows the two states' Q-functions after 54.3% losses. The two Gaussians moved closer together, the overlap 
has increased. In the ultimate limit of 100% loss, a pure vacuum state (cf. Fig. CJ would be registered by Bob. 



V. APPLICATION TO A CONTINUOUS VARIABLE QKD SCHEME 

We now apply our prepare&measure system to a specific quantum key distribution scheme. Alice prepares either the 
coherent state | + a) or | — a) as signal. As shown in the previous sections, Alice and Bob can verify the entanglement 
in their virtually shared state by simultaneously measuring both quadratures (or polarizations) and thereby recording 
the Q-function of the received states. In this section, we want to demonstrate a key generation system, which is based 
on postselection of Bob's measurement results. The idea of postselection of continuous variable data was introduced 
by Hirano et al. [sj and Silberhorn et al. The implementation with a discrete set of states was demonstrated 

in 1^ I451 14^. The idea for the simultaneous measurement setup was already demonstrated in [s^l and further 
elaborated in p35| . 

To estimate the efficiency of our experiment of generating key pairs we make three assumptions. The first concerns 
the excess noise produced by the quantum channel. We have shown in the previous section that this excess noise is 
always less than 0.02 shot noise units and that we are clearly within the regime of quantum correlations. We expect 
that the influence on the key rate is small for these values of the channel excess noise. Therefore, we neglect this 
excess noise in a first approximation and assume a noiseless quantum channel. A full security analysis, however, will 
have to take noisy quantum channels into account. 



FIG. 9: Mixed Q-function of the two signal states pi and p2 in balanced mixture after experiencing 54.3% of channel loss. This 
Q-function corresponds to the highlighted line in Table Q 
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FIG. 10; Both Q-functions of the pi and the p2 state, measured directly after preparation. This figure corresponds to Fig. |S| 

The second assumption concerns the local oscillator. As already mentioned in section III we transmit the local 
oscillator mode and the signal mode through the quantum channel, and manipulate both by polarization optics. We 
assume also in this section that the classical local oscillator mode is not manipulated by Eve. 

Our third assumption is that Eve performs a collective attack, which consists of an individual interaction of Eve's 
ancilla states with the signals and a coherent measurement onto those states. Eve is allowed to delay her measurement 
after the classical post-processing step in the protocol is completed to optimize her attack. In this scenario, a lower 
bound on the secret key rate G is then given by Devetak and Winter p7| 



whereas Ia-.b denotes the mutual information between Alice and Bob. The Holevo quantity XHoievo is a function of 
the states that Eve holds and quantifies her knowledge about the data. 

With these assumptions, we estimate the secret key rate while using either direct or reverse reconciliation combined 
with postselection. The estimation of the key rates are based on the derivation given in T^l . In a reverse reconciliation 
scheme, the key is built from Bob's measured data to improve the key rate j33j . This can be achieved by using suitable 
one-way protocols in the classical post-processing phase of the protocol. 

The characteristic action of postselection on the data rate can be seen from Fig. 1121 The experimental measurement 
data from the last line in Table HI is used to demonstrate the general effect of postselection on a joint probability 
distribution p{A; B) derived from our experiment. After the postselection step, Alice and Bob share correlated data 
from which they deduce a binary raw key by assigning a '0' bit value to negative measurement results, and a '1' bit 
value to positive measurement results. The x-axis of Fig. 1121 shows the postselection threshold r; only data points 
with IS2I > T are used to generate the raw key pair. The open squares show the fraction of the data points which 
are postselected. The black circles show the average error rate of the raw key after postselection. It can be seen that 



G > Ia:B — XHoh 



.evo : 



(15) 
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FIG. 11: Both Q-functions of the pi and the p2 state, measured after propagation with 54.3% losses. This figure corresponds 
to Fig.H 
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FIG. 12: Experimental analysis of relative acceptance and average error rate depending on the postselection threshold. Open 
squares: Fraction of accepted states after applying a postselection threshold of r. Black circles: remaining average error rate 
in the postselected pulses. This measurement was produced with a a channel loss of 51.7% (cf. Table|IJ last line). 



the postselected fraction depends on the threshold r as expected, but also that the average error rate decreases with 
increasing threshold, as data points with higher absolute value are less ambiguous than data points with low absolute 
value (cf. also i31|). In this sense the plotted error rate is averaged over all accepted data points, whether the originate 
from low absolute values with high error probability or from high absolute values with low error probability. 

A refined version of the postselection procedure uses an analysis which defines effective binary information channels 
between Alice and Bob to estimate the mutual information Ia:B between Alice and Bob and the Holevo quantity 
XHoievo- It is described in [l^ and can be used to determine the secret key rate G for direct reconciliation using 
postselection and reverse reconciliation j^. By using these information channels, one can determine the mutual 
information and Eve's knowledge about the data separately for each channel. The secret key rate can be optimized 
over Alice's input signal strength. Furthermore, it is possible to include the fact that an y im plementation of an error 
correction scheme cannot reach the theoretical performance limit given by Shannon |48l |49j . 

Following the calculations in can predict the key rates for a realistic error correction protocol that is 

assumed to perform as efficient as the widely used error correction protocol Cascade j50j |. The pulse rate for the 
experiment was 100 kPulse/s, the signal rate was 16.7 kPulse/s due to calibration. For the experiments of Table HI 
the key rates are shown in Table Hll With the setup used, clock rates up to 2MPulse/s are feasible, with no need for 
calibration (vacuum pulses) in the case of key generation, thus much higher secret key rates will be achieved in future 
experiments. 
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State Quantum Key rate Key rate 
overlap channel DR and RR and 

(— a| + q) transmission T postselection postselection 



0.50 


45.7% 


0.0027 


0.0168 


0.77 


45.7% 


0.0004 


0.0025 


0.52 


48.3% 


0.0038 


0.0194 


0.65 


48.3% 


0.0021 


0.0106 


0.51 


65.0% 


0.0244 


0.0562 



TABLE 11: Relative key rates for the experimental data, assuming realistic error correction and no channel excess noise. DR 
stands for direct reconciliation, RR for reverse reconciliation. 



VI. CONCLUSIONS 

We presented an experiment to verify the entanglement intrinsically present in Alice's and Bob's preparation and 
measurement data in a prepare&measure quantum key distribution experiment. Under the assumption that the local 
oscillator cannot be used by Eve to gain any information we built a coherent state measurement setup with high 
quantum efficiency and low added noise. For two overlapping coherent states prepared by Alice, we show that the 
joint probability distribution p{A; B) can only be explained by effective entanglement between Alice and Bob. This 
is the precondition for establishing a secret shared key [3. fHl l5ll|. In addition, by our special measurement setup 
we reconstruct Husimi's Q-function for the states received by Bob, which is useful in detecting manipulations in the 
quantum channel. We show that the excess noise of our coherent states is within the measurement accuracy, and 
less than 2% of the variance of the shot noise. With this low noise, many attacks by Eve can be ruled out for a 
large range of transmission losses, allowing longer distance key distribution without compromising the security. By 
applying postselection to our measurement data, we showed that a secure key can be generated when Eve is restricted 
to use the beam splitting attack. 
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